General Data Privacy and Security 3 — Questions and Answers
Question 1: What is 'ransomware'?
- Software that monitors employee productivity
- Malware that encrypts victim data and demands payment for decryption (Correct answer)
- A tool used by hackers to steal login credentials
- A virus that deletes system files permanently
Correct answer: Malware that encrypts victim data and demands payment for decryption
Ransomware is malicious software that encrypts a victim's files and demands a ransom payment, typically in cryptocurrency, in exchange for the decryption key.
Question 2: Which principle ensures that data is accurate and trustworthy and has not been altered improperly?
- Confidentiality
- Availability
- Integrity (Correct answer)
- Accountability
Correct answer: Integrity
Integrity is the CIA Triad principle that ensures data remains accurate, consistent, and unaltered except through authorized processes.
Question 3: What is a 'zero-day vulnerability'?
- A software flaw that has been patched within 24 hours
- A security flaw unknown to the vendor with no existing patch (Correct answer)
- A vulnerability that only affects systems with no updates installed
- A newly discovered password exploit
Correct answer: A security flaw unknown to the vendor with no existing patch
A zero-day vulnerability is a software security flaw that is unknown to the software vendor and therefore has no available patch, making it highly dangerous.
Question 4: What is the purpose of a 'firewall' in network security?
- To encrypt all outgoing data transmissions
- To monitor and control incoming and outgoing network traffic based on rules (Correct answer)
- To back up data automatically to the cloud
- To scan emails for phishing attempts
Correct answer: To monitor and control incoming and outgoing network traffic based on rules
A firewall enforces a security policy by filtering network traffic based on predefined rules, blocking unauthorized access while allowing legitimate communication.
Question 5: Which U.S. law governs the privacy of health-related information held by healthcare providers and insurers?
- FERPA
- GLBA
- HIPAA (Correct answer)
- CCPA
Correct answer: HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting sensitive patient health information from disclosure without consent.
Question 6: What does 'social engineering' mean in cybersecurity?
- Building secure social media platforms
- Manipulating people into divulging confidential information or performing actions (Correct answer)
- Automating social network monitoring
- Encrypting communications on social platforms
Correct answer: Manipulating people into divulging confidential information or performing actions
Social engineering exploits human psychology rather than technical vulnerabilities to trick individuals into revealing sensitive information or granting unauthorized access.
Question 7: What is the role of a Data Protection Officer (DPO)?
- To enforce criminal penalties for privacy violations
- To oversee an organization's compliance with data protection laws (Correct answer)
- To develop encryption algorithms for the company
- To approve all data deletion requests from customers
Correct answer: To oversee an organization's compliance with data protection laws
A DPO is responsible for ensuring an organization complies with applicable data protection regulations, advising on obligations, and serving as a point of contact for regulators and individuals.